NordVPN researchers uncover Android banking trojan campaign
Our threat intelligence team has uncovered a widespread malware campaign that tricks Android users into installing a banking trojan disguised as a legitimate app, giving attackers remote access to infected phones. The attackers impersonate more than 65 trusted brands and organizations, ranging from major airlines to tax authorities, government registries, social security systems, utilities, and retailers.
The campaign has operated since at least August 2025 and has targeted users across Europe, Asia, Africa, and Latin America. Rather than relying on a single impersonated company or type of scam, the attackers continually adapt their approach to different countries and services.
You might first encounter the scam through SMS, WhatsApp, or social media, with a believable reason to act, such as an airline job opening, a pending tax refund, an ID renewal, a pension verification request, or discounted flights. The message directs you to a fraudulent website designed to resemble the organization being impersonated, which then encourages you to download a malicious Android app.
Attackers impersonate airlines, governments, and other trusted services
The campaign stands out for the sheer variety of organizations the attackers impersonate. Our researchers identified more than 65 impersonated brands and services, including airlines, tax authorities, government registries, social security systems, healthcare providers, utilities, and retailers.
Airlines are among the most frequently impersonated organizations in the campaign. Fraudulent websites have impersonated Ryanair, Emirates, Qatar Airways, Air India, South African Airways, SriLankan Airlines, Saudia, and Garuda Indonesia. Attackers can then build convincing lures around familiar situations, such as job applications, ticket promotions, or discounted flights.
The campaign also impersonates government and public services, including tax authorities, immigration services, civil registries, and pension services. Retail and private-sector brands, including Woolworths, Makro, Takealot, DStv, Rappi, and Bank of Africa, have also been impersonated.
How the banking trojan reaches Android phones
When you follow the link, it opens a fraudulent website that resembles the organization the attackers are impersonating. The attackers adapt the pages to different countries and languages, helping them resemble the legitimate services you would expect to see where you live.
The fake website then prompts you to download and install an Android app. Installing it is the key step in the attack because it gives the malware access to parts of your phone that the fake website alone cannot reach.
The attackers also regularly change the web addresses they use, allowing the campaign to continue even when individual scam sites disappear or are taken down.
What the malware can do after installation
After installation, the malware can run in the background even after the phone restarts. It requests Android permissions that can give attackers access to sensitive information and let them monitor or control parts of your phone.
The analyzed malware samples could read SMS messages, access contacts and call logs, capture the screen, record audio, and activate the camera. The malware also requested permissions that could let it appear over other apps and keep running in the background, giving attackers far more access than any legitimate airline, retailer, or government app would reasonably need.
SMS interception puts your bank accounts at risk
One of the malware’s most serious capabilities is reading incoming SMS messages. If a bank sends a one-time verification code by text, the malware can expose that code to the attacker.
Access to your SMS verification codes, screen, and other sensitive data can make SMS-based two-factor authentication less effective and help attackers access your accounts or approve fraudulent transactions.
How to protect yourself from fake Android apps and banking trojans
To reduce the risk of installing a malicious app through campaigns like this, follow these practical precautions:
- Install apps only from official sources. If an airline, bank, or government service sends you a link asking you to install an Android app, avoid downloading it directly from the message. Instead, look for the app yourself on official app stores such as Google Play.
- Check the full web address before trusting a page. Attackers can include familiar brand names in fraudulent domains to make them appear legitimate. Our researchers observed suspicious domains using extensions such as .cc, .lol, .xyz, .mom, and .pw.
- Don’t treat HTTPS as proof that a website is legitimate. The padlock in your browser indicates that the connection is encrypted, but it does not verify that the site actually belongs to the organization it claims to represent.
- Pay attention to unusual permission requests. Be cautious if an app asks for permissions unrelated to its function, such as accessing your SMS messages or call logs, recording your screen, or using your microphone and camera.
- Verify suspicious links before opening them. NordVPN’s Link Checker can help you assess whether an unfamiliar URL may be malicious before you visit it.
NordVPN’s next-gen antivirus with scam alert and malware protection can also help block malicious websites and scam domains when you try to open them.
If you have already installed an app you suspect may be malicious, disconnect your phone from the internet and uninstall the app. Change important passwords from another trusted device and contact your bank immediately if your financial accounts may have been exposed.
Methodology
Our threat intelligence team analyzed 10 Android malware samples and grouped them based on the certificates used to sign the apps. The researchers examined the permissions, app components, domains, and hosting patterns associated with each sample to identify connections between them and the services they impersonated.
Because the apps used different package names across versions, their signing certificates provided a more consistent way to identify related samples.
Online security starts with a click.
Stay safe with the world’s leading VPN